# Managing "is\_write\_index"

**URL:** <https://discuss.elastic.co/t/managing-is-write-index/256089>\
**Category:** Elasticsearch\
**Created:** [November 20, 2020, 8:41am UTC](https://discuss.elastic.co/t/managing-is-write-index/256089 "2020-11-20T08:41:35Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![koos](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/koos/32/73808_2.png) [@koos](https://discuss.elastic.co/u/koos)\
**Post date:** [November 20, 2020, 8:41am UTC](https://discuss.elastic.co/t/managing-is-write-index/256089/1 "2020-11-20T08:41:35Z")

</div>

Hi there,

We've created a Lambda function (python) in order to steam logs from AWS CloudWatch to our ELK stack. I'm also making use of life cycle policies to rotate the index on a specific size and delete after the specified days.

The python script creates an index in this format: cwl-xxxxxx-20201120-0001. When the index is created, I set "is\_write\_index : True"

However, on the next day, when creating a new index for the day with the Lambda function, I get the following error:

```auto
alias [cwl-xxxxxx] has more than one write index [cwl-xxxxxx-2020.11.20-0001,cwl-xxxxxx-2020.11.19-000002].

```

I understand that I can only have one write index, but how do I manage that? I thought that when setting the write index on the new index, it will be removed from the previous index?

I think I'm just missing something here. Any advice would be greatly appreciated.

---

<div class="post-metadata">

**Author:** ![Wolfram\_Haussig](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wolfram_haussig/32/70528_2.png) [@Wolfram\_Haussig](https://discuss.elastic.co/u/Wolfram_Haussig)\
**Post date:** [November 20, 2020, 8:46am UTC](https://discuss.elastic.co/t/managing-is-write-index/256089/2 "2020-11-20T08:46:09Z")

</div>

Hi,

Have a look [here](https://www.elastic.co/guide/en/elasticsearch/reference/7.10/indices-aliases.html): At the bottom of the page there is an example how to atomically switch the write index. Basically, you create the index without is\_write\_index and use the alias API to switch the write index to the new one.

```auto
POST /_aliases
{
  "actions": [
    {
      "add": {
        "index": "test",
        "alias": "alias1",
        "is_write_index": false
      }
    }, {
      "add": {
        "index": "test2",
        "alias": "alias1",
        "is_write_index": true
      }
    }
  ]
}

```

Best regards  
Wolfram

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [November 20, 2020, 8:50am UTC](https://discuss.elastic.co/t/managing-is-write-index/256089/3 "2020-11-20T08:50:38Z")

</div>

If you are using ILM with rollover you should write directly to the write alias and not a specific index name. ILM will then behind the scenes roll indices as required as per the policy configuration. ILM will switch the write alias to point to the correct index.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 18, 2020, 8:50am UTC](https://discuss.elastic.co/t/managing-is-write-index/256089/4 "2020-12-18T08:50:49Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
